ci: call the org leak-scan workflow - #6
Merged
Merged
Conversation
Verified clean against this rule set before wiring: a fresh clone scanned with no findings in the worktree or in history.
…ADME The rule table names what each rule catches, the lookahead explanation names the sibling repo it once missed, and the allowlist example shows a realistic match string. A doc that cannot say any of that documents nothing. Four entries, each scoped to rule+path+match per the contract this repo's own tests enforce.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Calls the org's shared leak-scan workflow, which checks that this repo publishes
its own work and nothing else: no other project's name from this org, no client's
name, no layout convention from the private monorepo, and no absolute path from an
authoring machine.
The whole change is one
uses:line. There is no pattern list here and no settingthat names this repo — the scanner derives that from
${{ github.repository }}, sothere is nothing in this file to keep in sync and nothing that can go stale.
Depends on #4 and #5; this PR's check stays red until
those land, then passes on re-run.
Test plan
A fresh clone of this repo was scanned with the same rule set before this was
wired up — no findings, in the worktree or anywhere in history. The gate is
therefore green from the start rather than being wired up over a known failure.